Observability

Invalid template received from Palo Alto Networks Prisma SD-WAN (CloudGenix) in Hybrid Cloud Observability 2022.2 and later

The following article describes recommended flow fields for export on Palo Alto Networks Prisma SD-WAN devices. The article is valid for Hybrid Cloud Observability 2022.2 and later.

First published date

5/5/2023 2:45 PM

Last published date

2/21/2025 12:12 AM

Overview

The following article describes recommended flow fields for export on Palo Alto Networks Prisma SD-WAN devices.
The article is valid for Hybrid Cloud Observability 2022.2 and later.

Product section

Hybrid Cloud Observability

Cause

Device is not sending all mandatory flow fields to Hybrid Cloud Observability.
Look for the following event in the “Last XX NetFlow Traffic Analyzer Events” widget:

Resolution

Set up the Prisma flow template to export the flow fields based on the following table:
NTA fieldIANA IDPrisma (CloudGenix) equivalent fieldImportance in NTA
Protocol4PROTOCOLMandatory
SourceAddress8SRC_IPV4_ADDRESSMandatory
DestAddress12DST_IPV4_ADDRESSMandatory
InterfaceRx10INTERFACESAt least one is mandatory
InterfaceTx14
Bytes1CONNECTION_UNIFLOW_BYTESMandatory
Packets2CONNECTION_UNIFLOW_PACKETSOptional
SourcePort7SRC_PORTOptional
DestPort11DST_PORTOptional
ApplicationID95APP_DEF_IDOptional

 
Additional resources

Required fields in SolarWinds NTA
Palo Alto Networks documentation (© 2023 Palo Alto Networks, Inc., available at https://docs.paloaltonetworks.com, obtained on May 5, 2023)